Skip to content

Advanced Security Testing

ISTQB Security Tester Training

Develop advanced software security testing skills and learn how to identify, assess and test security risks before they become serious vulnerabilities.

The ISTQB Advanced Level Security Tester (CT-SEC) course is designed for experienced testing professionals who want to specialise in security testing and build deeper expertise in security risk, vulnerabilities, security controls, test strategy and security testing throughout the software lifecycle.

Learn how to approach security testing systematically, from identifying assets and risks to testing authentication, authorisation, encryption, firewalls and other security mechanisms.

3-day instructor-led course
Official courseware & sample exams
ISTQB exam included
Classroom or Live Virtual
Exam prep and study plan included
Exam prep meeting

Specialist Security Testing

Build the Skills to Test Software for More Than Functionality

A system can pass every functional test and still expose sensitive information, allow unauthorised access or contain vulnerabilities that attackers can exploit.

That is why security testing requires a different mindset.

The ISTQB Security Tester training course develops the advanced knowledge needed to evaluate software from a security perspective — understanding what must be protected, where risks exist, how attackers may exploit weaknesses and whether security controls actually work.

You’ll learn how to design and manage structured security testing based on risk, security policies, known vulnerabilities and business priorities, rather than relying on ad hoc security checks.

Attend live virtual training from anywhere across Africa, join classroom training in South Africa, or arrange private corporate training for your team.

About the course

What Is ISTQB Security Tester?

The ISTQB Advanced Level Security Tester (CT-SEC) certification is an advanced specialist qualification for experienced software testing professionals who want to deepen their expertise in security testing.

The course builds on your existing testing knowledge and applies it to the particular challenges of software and information security.

You’ll explore how security risks are assessed, how security test strategies are developed, how tests are designed around vulnerabilities and threats, and how security mechanisms such as authentication, authorisation, encryption and firewalls can be evaluated.

The qualification is aimed at professionals who have already reached an advanced point in their software testing careers and want to specialise further in security testing.

120+

Countries recognise this certification

#1

Software testing qualification globally

9

Syllabus chapters covered over 3 days

65%

Pass mark required on the certification exam

syllabus

What Does the ISTQB Security Tester Course Cover?

The ISTQB Security Tester (CT-SEC) course develops advanced knowledge across the key areas needed to assess security risks, design effective security tests, evaluate vulnerabilities and security controls, and manage security testing throughout the software lifecycle.

The Basis of Security Testing

Build the foundation needed to approach software security testing from a risk-based perspective.

You’ll learn how assets, threats, vulnerabilities and potential business impacts influence security testing, while exploring security policies, procedures and security audits. The chapter helps you understand how to determine what needs to be protected, where the greatest security risks exist and where testing should focus first.

Security Testing Purposes, Goals & Strategies

Learn how to turn security risks and organisational requirements into a focused security testing strategy.

You’ll explore how business objectives, security policies, stakeholders and the software lifecycle influence security test objectives and approaches. You’ll also examine why security testing strategies fail and how testing practices can be improved to provide more meaningful evidence about a system’s security.

Security Testing Processes

Understand how professional security testing is planned and performed as a structured process rather than a collection of isolated security checks.

You’ll learn how to define an effective security testing process, adapt it to different software development lifecycles and plan security testing based on project risks and objectives. The chapter also explores test analysis, design, implementation, execution, evaluation and maintenance, including considerations around activities such as social engineering and password-related attacks.

Security Testing Throughout the Software Lifecycle

Learn how to integrate security testing throughout software development so that vulnerabilities can be identified before they become expensive or dangerous production problems.

You’ll explore the role of security testing during requirements, design, implementation, component and integration testing, system testing, acceptance testing and maintenance. You’ll also examine security-focused approaches such as abuse cases and fuzz testing and understand how security testing changes across different stages of development.

Testing Security Mechanisms

Develop practical knowledge of how to evaluate the security controls and mechanisms organisations rely on to protect systems, users and sensitive information.

You’ll explore areas including system hardening, authentication, authorisation, encryption, firewalls, network zones, intrusion detection, malware protection, vulnerability scanning and data protection techniques. The focus is not simply on knowing what these mechanisms do, but understanding how a Security Tester can assess whether they are actually providing the protection expected.

Human Factors in Security Testing

Understand why some of the biggest security vulnerabilities involve people rather than technology.

You’ll examine attacker behaviour and motivation, common attack scenarios and the ways human behaviour can introduce security risks. The chapter also explores social engineering and security awareness, helping you understand how attackers think and why people, processes and technology all need to be considered when assessing security.

Security Test Evaluation & Reporting

Learn how to turn security testing results into information that organisations can actually use to make better security decisions.

You’ll explore how security findings should be evaluated against expectations and acceptance criteria, how sensitive security results should be protected, and how security test status, vulnerabilities and risk information should be communicated to the appropriate stakeholders.

Security Testing Tools

Understand where security testing tools add value and how to select them based on the testing problem rather than simply choosing the most popular product.

You’ll explore different types of security testing tools, including the role of static and dynamic analysis, and learn how to identify tool requirements, assess open-source security tools and evaluate vendor capabilities. The goal is to help you make informed tool choices that support your wider security testing strategy.

Standards & Industry Trends

Understand how recognised security standards and industry practices can strengthen and guide your organisation’s security testing approach.

You’ll learn why security testing standards matter, where they can be found, how regulatory and contractual requirements influence their use, and how to select and apply appropriate standards within different organisational and project environments.

COURSE INFORMATION

ISTQB Security Tester Training at a Glance

Training Duration

3-days

Training Delivery

Live Virtual | Classroom | Corporate

Accreditation

ISTQB & SASTQB Accredited

Exam Infomration

Prepare for the ISTQB Security Tester Exam With Confidence

The certification exam is administered under SASTQB, the official ISTQB body for Southern Africa. Your exam voucher is included in the course price — no separate booking needed.

45 Questions

Multiple choice format

120 Minutes

+25% extra time for non-native speakers

65% Pass Mark

52 out of 80 marks required

Prerequisite

ISTQB Foundation Level (CTFL) Certificate

WHY CT-SEC

Why Get Certified as an ISTQB Security Tester?

Security testing is no longer a niche activity reserved for the final stages of a project.

Modern software systems handle sensitive data, financial information, identities, transactions and critical business processes. That means security weaknesses can create significant operational, financial and reputational risk.

Understand Security Risk More Deeply

Learn how threats, vulnerabilities, assets, likelihood and business impact influence the way security testing should be prioritised.

Test Beyond Functional Requirements

Develop the mindset needed to identify weaknesses that may not appear during ordinary functional testing.

Evaluate Security Controls

Build knowledge for testing authentication, authorisation, encryption, firewalls, intrusion detection, hardening and other mechanisms designed to protect systems and data.

Find Vulnerabilities Earlier

Understand how security testing can be integrated throughout the software lifecycle so weaknesses can be identified before release.

Strengthen Your Technical Testing Profile

Add advanced security testing expertise to your software testing skill set and broaden the value you can bring to complex projects.

Support Better Security Decisions

Learn how to evaluate findings and report security risks in a way that helps technical and business stakeholders prioritise remediation.

WHO SHOULD ATTEND?

Who Is ISTQB Security Tester Training For?

ISTQB CT-SEC is designed for experienced software testing professionals who want to specialise in security testing or take greater responsibility for security-related testing activities.

Already Working in Technical Testing?

If you already work in technical testing, CT-SEC helps you extend your skills into security risk, vulnerabilities, security controls and advanced security test strategy.

Moving Into Security Testing?

If you have a strong software testing foundation and want to move into a security-focused role, CT-SEC provides a structured path into advanced software security testing.

The course is particularly relevant for:

Software Testers
Security Testers
Technical Test Analysts
Test Analysts
Test Engineers
QA Engineers
Quality Engineers
Test Leads
Test Managers
Test Consultants
Software Developers
Security Professionals
DevSecOps Professionals
Quality Managers

Why Impimpi Technologies

Learn Security Testing From Software Testing Specialists

Security testing sits at the intersection of software quality, technical risk and information security.

That makes it important to learn from people who understand testing as a profession, not simply cybersecurity tools.

Accredited ISTQB Training

We’re software testing specialists. Our training is grounded in a deep understanding of testing, quality engineering and the challenges testing professionals face in practice.

Practitioner-Led Training

Our approach connects internationally recognised testing principles with an understanding of how testing works in real software environments.

Software Testing Specialists

We’re not a general technology training company. Software testing is our speciality.

Our work spans training, consulting and specialist recruitment, giving us a broader understanding of the skills testing professionals and organisations need.

More Than Exam Preparation

Certification matters, but so does understanding how to apply what you’ve learned.

Our goal is to help you understand the concepts, not simply memorise them for an exam.

AFTER ISTQB CT-SEC

Continue Building Your Technical & Security Testing Skills

Completing the ISTQB Security Tester certification gives you advanced specialist knowledge in software security testing.

From here, you can continue building technical expertise based on your role and career direction.

ISTQB Advanced Technical Test Analyst

Develop deeper technical testing knowledge across white-box testing, static and dynamic analysis, performance, security and other technical quality characteristics.

ISTQB Advanced Test Automation Engineering

Build advanced skills in designing, implementing and continuously improving sustainable test automation solutions.

FREQUENTLY ASKED QUESTIONS

ISTQB Security Tester Training FAQs

Find answers about ISTQB CT-SEC training courses

Develop the Skills to Test What Attackers Look For

Software can behave exactly as expected and still contain weaknesses that put data, systems and users at risk.

Develop advanced skills in security risk assessment, vulnerability testing, security controls and structured software security testing while preparing for your ISTQB Advanced Level Security Tester certification with Impimpi Technologies.

Understand the threat. Test the defence. Reduce the risk.